documenti_personali.exe - Dangerous
documenti_personali.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
W32.Vispat.C@mm is a mass-mailing worm that gathers email addresses from the compromised computer. It also changes the home page for Internet Explorer and lowers Internet security settings on the compromised computer.
Related files:
%UserProfile%\Application Data\Microsoft\Address Book\[USER NAME].wab
%UserProfile%\Local Settings\Application Data\Identities\{RANDOM CLSID}\Microsoft\Outlook Express\Folders.dbx
%UserProfile%\Local Settings\Application Data\Identities\{RANDOM CLSID}\Microsoft\Outlook Express\Inbox.dbx
%UserProfile%\Local Settings\Application Data\Identities\{RANDOM CLSID}\Microsoft\Outlook Express\Offline.dbx
%System%\officeparam.dll
%System%\scansvc\trust\documenti_personali.exe
%System%\windowslite.pbk
%SystemDrive%\documenti.zip
Kill the process documenti_personali.exe and remove documenti_personali.exe from Windows startup.